TinyFish runs AI web agents for companies like Google, DoorDash, and ClassPass, and it now accepts Sign in with AgentID. An agent working on TinyFish can hold its own account, under its own verified identity, instead of running on a key a human pasted in.
In short
- TinyFish is enterprise infrastructure for AI web agents: Search, Fetch, Browser, and Agent APIs behind a single key, with usage metered against a shared wallet.
- At enterprise scale the caller is a fleet, and a fleet on one shared credential is unattributable by construction.
- With Sign in with AgentID, an individual agent can establish its own account under its own verified identity.
- Identity arrives over OpenID Connect: a stable identifier plus a working email address that belongs to the agent.
- TinyFish keeps control of its APIs, wallet, metering, and policy at every stage.
What is TinyFish?
TinyFish is enterprise infrastructure for AI web agents, backed by a $47 million Series A led by ICONIQ. Behind one API it offers four capabilities: Search for structured results from live pages, Fetch for turning any URL into clean markdown or JSON, Browser for cloud sessions that hold up against bot detection, and Agent for multi-step web automation. TinyFish reports 89.9 percent on Mind2Web, the standard benchmark for web task automation.
Enterprises use it to automate the workflows that live on other people's websites: quoting, monitoring, inventory checks, market intelligence. So TinyFish's traffic is fleets of agents working around the clock, not a developer at a keyboard.
What breaks when a whole fleet runs on one credential?
Accountability breaks in both directions. A fleet behind one shared key looks like a single anonymous blob of usage. The platform cannot say which agent did what; the enterprise cannot cleanly answer where a given action came from when a workflow touches something it should not have; and one leaked credential is every agent's credential.
This matters more for TinyFish than for most platforms, because its agents act on the open web on real companies' behalf. The further an agent's actions reach, the more the question "which agent was that, exactly" needs a crisp answer, and a shared key guarantees it never has one.
The unit of accountability should be the agent, and that requires the agent to hold an account.
How does an agent in a fleet get its own account?
It signs in as itself. TinyFish accepts AgentID, AgentMail's sign-in service for AI agents, which runs on OpenID Connect, the same standard behind Sign in with Google. Each agent's identity is anchored to something it owns, its AgentMail inbox, and the sign-in delivers a verified email address and a stable identifier to TinyFish. The agent approves each sign-in with a single-use cryptographic signature from its own key. No password exists in the flow, and no human is needed to mint or distribute credentials.
At fleet scale the properties compound. Fifty agents hold fifty inboxes, so they arrive as fifty distinct, attributable account holders. Each returns to its own account on every sign-in because the identifier is stable. And each address is a working mailbox, so usage alerts, receipts, and account notices land with the account holder they concern, not in a shared inbox nobody owns.
Who controls what
| Stage | AgentID | TinyFish |
|---|---|---|
| Identity at sign-in | Supplies verified agent email and stable identifier through OpenID Connect | Accepts the sign-in, creates the account |
| API access and keys | Not involved | Issues and scopes them per account |
| Wallet, metering, and billing | Not involved | Controls all three |
| What the agent may automate | Not involved | Governed by TinyFish's product and policy |
| Rate limits and abuse response | Not involved | Enforced per account, now attributably |
| Account email | Provides the inbox behind the identity | Decides which messages it sends |
What does per-agent identity buy an enterprise?
An audit trail that matches reality. When each agent is an account, usage reports say which agent consumed what, incident questions have a lookup instead of an investigation, and retiring one agent means closing one account rather than rotating a credential fifty processes depend on.
It also cleans up the security posture. No shared secret circulates through the fleet, and revoking one agent's sign-in credential touches exactly one agent. The blast radius of any single compromise shrinks to the account it happened in.
TinyFish, meanwhile, gains customers it can see. Fleet traffic stops being a blob and becomes accounts it can meter, limit, and reason about individually, with its own controls unchanged.
Start at TinyFish. The AgentID sign-in guide covers preparing an agent's inbox identity before its first sign-in.
